Echo: linux: security update to 6.1.159-1

medium Tenable Self-Hosted Container Security Plugin ID 455571

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: usb: storage: Fix memory leak in USB
bulk transport A kernel memory leak was identified by the 'ioctl_sg01' test from Linux Test Project (LTP).
The following bytes were mainly observed: 0x53425355. When USB storage devices incorrectly skip the data
phase with status data, the code extracts/validates the CSW from the sg buffer, but fails to clear it
afterwards. This leaves status protocol data in srb's transfer buffer, such as the US_BULK_CS_SIGN 'USBS'
signature observed here. Thus, this can lead to USB protocols leaks to user space through SCSI generic
(/dev/sg*) interfaces, such as the one seen here when the LTP test requested 512 KiB. Fix the leak by
zeroing the CSW data in srb's transfer buffer immediately after the validation of devices that skip data
phase. Note: Differently from CVE-2018-1000204, which fixed a big leak by zero- ing pages at allocation
time, this leak occurs after allocation, when USB protocol data is written to already-allocated sg pages.
(CVE-2025-68288)

Solution

Update the linux library and its related packages to version 6.1.159-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2025-68288

Plugin Details

Severity: Medium

ID: 455571

Version: Revision 1.2

Type: Local

Published: 10/1/2026

Updated: 10/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.63

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2025-68288

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 12/17/2025

Vulnerability Publication Date: 12/9/2025

Reference Information

CVE: CVE-2025-68288